Get the latest tech news

10-Year-Old Open Source Flaw Could Affect 'Almost Every Apple Device'


storagedude shares a report from the Cyber Express: Some of the most widely used web and social media applications could be vulnerable to three newly discovered CocoaPods vulnerabilities -- including potentially millions of Apple devices, according to a report by The Cyber Express, the news service ...

storagedude shares a report from the Cyber Express: Some of the most widely used web and social media applications could be vulnerable to three newly discovered CocoaPods vulnerabilities-- including potentially millions of Apple devices, according to a report by The Cyber Express, the news service of threat intelligence vendor Cyble Inc. E.V.A Information Security researchers reported three vulnerabilities in the open source CocoaPods dependency manager that could allow malicious actors to take over thousands of unclaimed pods and insert malicious code into many of the most popular iOS and MacOS applications, potentially affecting "almost every Apple device." The researchers found vulnerable code in applications provided by Meta (Facebook, Whatsapp), Apple (Safari, AppleTV, Xcode), and Microsoft (Teams); as well as in TikTok, Snapchat, Amazon, LinkedIn, Netflix, Okta, Yahoo, Zynga, and many more. The newly discovered vulnerabilities -- one of which (CVE-2024-38366) received a 10 out of 10 criticality score -- actually date from a May 2014 CocoaPods migration to a new 'Trunk' server, which left 1,866 orphaned pods that owners never reclaimed.

Get the Android app

Or read this on Slashdot

Read more on:

Photo of Year

Year

Photo of apple device

apple device

Photo of old open source flaw

old open source flaw

Related news:

News photo

'Almost every Apple device' vulnerable to CocoaPods supply chain attack

News photo

OpenAI CEO Sam Altman anticipates GPT-5 as a “significant leap forward” over GPT-4, which occasionally “goes off the rails” with mistakes even a six-year-old wouldn’t make

News photo

Win a gold-plated PS5 and tickets to next year’s final by proving your worth in the official Wimbledon e-sports tournament